Skip to content
https://logotyp.us

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
95
GRADE
A
FIX
0
REVIEW
4
PASS
13
INFO
0
Probed from Madrid, Spain
200 OK
Checks
17
13 PASS 4 REVIEW
C
Reverse DNS
Action
0/4 IPs match cert SAN
REVIEW
0/4 IPs match cert SAN
Info::
PTR lookup failed for 188.114.96.2: lookup 188.114.96.2: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
Info::
PTR lookup failed for 188.114.97.2: lookup 188.114.97.2: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
Info::
PTR lookup failed for 2a06:98c1:3121::2: lookup 2a06:98c1:3121::2: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
Info::
PTR lookup failed for 2a06:98c1:3120::2: lookup 2a06:98c1:3120::2: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
B
TLS Certificate Expiry & Recommendations
84 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

84
days left
0d 30d 60d 90d+

Recommended actions

  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: 404, /health: 404, /healthz: 404, /ping: 404, /status: 404.
A+
DNS Records
2 A records, 56 ms lookup
PASS
2 A records, 56 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 188.114.96.2, 188.114.97.2
Info::
Has 2 IPv6 (AAAA) record(s)
Got: 2a06:98c1:3121::2, 2a06:98c1:3120::2
Info::
2 nameserver(s) configured
Got: jonah.ns.cloudflare.com, rose.ns.cloudflare.com
Info::
3 mail exchanger(s) configured
Info::
SPF record present in TXT
Info::
DNS resolution time: 56 ms
Got: 56 ms
A188.114.96.2, 188.114.97.2
AAAA2a06:98c1:3121::2, 2a06:98c1:3120::2
CNAME—
NSjonah.ns.cloudflare.com, rose.ns.cloudflare.com
MX
4 isaac.mx.cloudflare.net
19 linda.mx.cloudflare.net
39 amir.mx.cloudflare.net
TXT
SPF v=spf1 include:_spf.mx.cloudflare.net ~all
google-site-verification=a4Zm4ohNpNGjfuIkVYDfpzThCgK4Au6IY7X4yIT83E8
CAALookup not available with standard resolver
Resolved in 56 ms
A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
DNSSEC
Signed and validating
PASS
Signed and validating
Info::
DNSSEC fully signed and chain validates (ECDSAP256SHA256)
A
CAA Records
issue: comodoca.com, digicert.com, letsencrypt.org, pki.goog, ssl.com | issuewild: comodoca.com, digicert.com, letsencrypt.org, pki.goog, ssl.com
PASS
issue: comodoca.com, digicert.com, letsencrypt.org, pki.goog, ssl.com | issuewild: comodoca.com, digicert.com, letsencrypt.org, pki.goog, ssl.com
Info::
CAA issue tag present — authorized CA(s): comodoca.com, digicert.com, letsencrypt.org, pki.goog, ssl.com
Info::
No CAA iodef tag — won't be notified of failed issuance attempts
Add `0 iodef "mailto:security@example.com"` to receive notifications when a CA refuses issuance because it doesn't match your CAA policy. Useful signal for detecting issuance attempts by unauthorized CAs.
A+
Multi-Resolver DNS Speed
Mean 23ms across 3 resolvers (spread 31ms)
PASS
Mean 23ms across 3 resolvers (spread 31ms)
Info::
Quad9: 6ms
Got: 6ms via 9.9.9.9:53
Info::
Cloudflare: 28ms
Got: 28ms via 1.1.1.1:53
Info::
Google: 37ms
Got: 37ms via 8.8.8.8:53
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://logotyp.us

https://logotyp.us

110 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://logotyp.us200110 msHTTP/1.1cloudflare
A+
IPv6 Readiness
IPv6 reachable (25 ms)
PASS
IPv6 reachable (25 ms)
Info::
IPv6 is configured and reachable at 2a06:98c1:3121::2, 2a06:98c1:3120::2
Got: 25 ms connect
IPv6 Ready
AAAA Records 2a06:98c1:3121::2, 2a06:98c1:3120::2 Connection Reachable (25 ms)
A+
Crawlability
robots.txt present, sitemap with 25460 URLs
PASS
robots.txt present, sitemap with 25460 URLs
Info::
robots.txt is present
Got: 1168 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 25460 entries
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 1168 B Sitemaps referenced 2 User-agents ClaudeBot, Bingbot, Google-Extended, DotBot, ChatGPT-User, Anthropic-ai, PerplexityBot, AhrefsBot, SemrushBot, Bytespider, Googlebot, Amazonbot, Meta-ExternalAgent, cohere-ai, MJ12bot, *, Googlebot-Image, Applebot, Yandex, DuckDuckBot, GPTBot Blocking No — crawling allowed
# Logotyp.us - Free Vector Logo Database
# Contact: https://logotyp.us | Twitter: @logotypus

# Default rules
User-agent: *
Disallow: /data/
Disallow: /fonts/
Disallow: /search/
Crawl-delay: 1

# Search Engines
User-agent: Googlebot
Allow: /

User-agent: Googlebot-Image
Allow: /file/
Allow: /img/

User-agent: Bingbot
Allow: /

User-agent: Applebot
Allow: /

User-agent: Yandex
Allow: /
Crawl-delay: 2

User-agent: DuckDuckBot
Allow: /

# AI/LLM Crawlers - Allowed (public logo database)
User-agent: GPTBot
Allow: /

User-agent: ChatGPT-User
Allow: /

User-agent: ClaudeBot
Allow: /

User-agent: Anthropic-ai
Allow: /

User-agent: PerplexityBot
Allow: /

User-agent: Google-Extended
Allow: /

User-agent: Amazonbot
Allow: /

User-agent: Meta-ExternalAgent
Allow: /

User-agent: cohere-ai
Allow: /

# Block aggressive/unwanted bots
User-agent: AhrefsBot
Crawl-delay: 10

User-agent: SemrushBot
Crawl-delay: 10

User-agent: MJ12bot
Disallow: /

User-agent: DotBot
Disallow: /

User-agent: Bytespider
Disallow: /

# Sitemaps
Sitemap: https://logotyp.us/sitemap.xml
Sitemap: https://logotyp.us/image-sitemap.xml

# AI Content Guide
# See also: https://logotyp.us/llms.txt
A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Info::
HTTP correctly redirects to HTTPS permanently
Got: HTTP 301

www / non-www

301https://www.logotyp.us/
200https://logotyp.us/

Preferred variant: non-www

HTTP → HTTPS

301http://logotyp.us/ → https://logotyp.us/

Consistent

A+
Domain Intelligence
logotyp.us — via Cloudflare, Inc., 9 years, 9 months old
PASS
logotyp.us — via Cloudflare, Inc., 9 years, 9 months old
Info::
Domain registered until Jan 25, 2027 (3 months remaining)
Info::
Registrar: Cloudflare, Inc.
Info::
Registrar lock is enabled
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Domain expiry

112 days

January 25, 2027

SSL certificate

84 days

Issued by Google Trust Services

Domain age

9 years, 9 months

Registered January 26, 2017

DNSSEC

Status unknown

Protects against DNS spoofing

Hosting

Unknown

2a06:98c1:3120::2

Registrar

Cloudflare, Inc.

Locked 2 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Registrar Cloudflare, Inc.
Created January 26, 2017 (9 years, 9 months ago)
Expires January 25, 2027 (3 months)
Last Updated December 31, 2025
Name Servers rose.ns.cloudflare.com, jonah.ns.cloudflare.com
Registrant NS
Hosting
IP Address 2a06:98c1:3120::2
Data source: whois (1.1s)

Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.

Why this matters

Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A+
HTTP Probe Timing
Total 278 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
51 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
25 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
31 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
277 ms
Total Time Total request time from DNS lookup through full response.
278 ms

Connection waterfall

DNS Lookup 51 ms TCP Connect 25 ms TLS Handshake 31 ms Server Processing 171 ms Content Transfer 1 ms
A
CDN & Delivery
Cloudflare (DYNAMIC)
PASS
Cloudflare (DYNAMIC)
Info::
Document is served via Cloudflare CDN (edge: CDG)
Got: cf-ray: a44eaa6fdef8d479-CDG
Info::
CDN cache status: DYNAMIC
Document served via CDN: Cloudflare
Provider Cloudflare Cache Status DYNAMIC Evidence cf-ray: a44eaa6fdef8d479-CDG
A+
CDN Cache Observability
Cache state: DYNAMIC
PASS
Cache state: DYNAMIC
Info::
CDN cache state observable via 5 header(s)
Got: age=0, cf-cache-status=DYNAMIC, x-cache=MISS, x-cache-hits=0, x-served-by=cache-mrs1530052-MRS
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback